OSVDB ID: 18802

Title: Legato NetWorker lgtomapper Unauthorized RPC Service Unregister DoS

Info

Disclosure

Aug 16, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Legato NetWorker contains a flaw that may allow a remote denial of service or an unauthorized information disclosure. The issue occurs because the lgtomapper RPC port mapper allows remote calls to the "pmap_set" and "pmap_unset" functions. A remote attacker could unregister NetWorker RPC services resulting in loss of availability for the service, or possibly register a new service which might allow eavesdropping on NetWorker process communications.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service, Information Disclosure
Impact: Loss of Confidentiality, Loss of Availability
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, EMC and Sun have released patches to address this vulnerability.

Products

Sun Microsystems, Inc.

StorEdge Enterprise Backup Software

7.0
7.1
7.2

Solstice Backup

6.0
6.1

EMC Corporation

Legato NetWorker

7.2
7.13
4.2.2
6.0
6.1

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/18802